HeadlinesBriefing favicon HeadlinesBriefing.com

Resolv DeFi Hack Prints $23M in Fake Stablecoins

Hacker News •
×

On March 22, 2026, the DeFi protocol Resolv fell victim to a swift exploit that printed tens of millions of unbacked stablecoins. An attacker deposited only $100‑$200 k in USDC, yet minted roughly 80 million USR tokens, triggering a sharp de‑peg and forcing the protocol to halt operations in the span of minutes, the attack exposed critical off‑chain vulnerabilities.

The breach hinged on Resolv’s reliance on an off‑chain service that signed mint approvals with a privileged key stored in AWS KMS. With that key compromised, the attacker could authorize any minting amount, bypassing on‑chain limits. The resulting $23 million extraction highlighted how cloud infrastructure can become the single point of failure for protocols.

Resolv’s minting logic never enforced a maximum ratio between deposited collateral and issued USR. The contract only checked for a valid signature, leaving the system vulnerable to any signed request. By converting USR to wstUSR, the attacker moved the tokens into a less liquid derivative, masking the flood in the market and loss.

The incident forced Resolv Labs to suspend all protocol functions and launch an investigation. It underscored that even audited contracts can be undone by compromised off‑chain keys. Real‑time on‑chain monitoring and automated response systems are now essential safeguards, proving that security must extend beyond the blockchain itself to protect users and maintain trust in DeFi.